NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2748 by repository stars
Last release 3 months ago
09 Jul 2026
Release timing varies
gaps range from 8 days to 4 months
Some releases are documented
notes for 10 of 40 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
93 releases · first in 2024
Nothing published for this version
skip persisting with version check when running in ci by @SUSTAPLE117 in #439
Full Changelog: v1.1.5...v1.1.6
One column per month.
Fix Default Branch Detection For Analysis by @SUSTAPLE117 in #437
Full Changelog: v1.1.4...v1.1.5
Reworked Refs Resolution by @SUSTAPLE117 in #423
Full Changelog: v1.1.3...v1.1.4
Nothing published for this version
This release focuses on core engine improvements , stability fixes , and modernization of the toolchain . The biggest shift is the move away from exec
poutine v1.1.3 🎉This release focuses on core engine improvements, stability fixes, and modernization of the toolchain. The biggest shift is the move away from exec-based Git operations toward a fully in-memory model using go-git, along with improved resiliency and observability during analysis.
⚡ In-Memory Git with go-git v6: Replaced exec-based Git operations with go-git using in-memory storage. This significantly improves performance, portability, and reduces reliance on system binaries, by @SUSTAPLE117.
(#400)
🛡️ Resilient Repository Batch Fetching: Improved robustness of repository batch fetching, reducing failures during large-scale analysis operations, by @SUSTAPLE117.
(#399)
📊 Analysis Progress Monitoring Improvements: Enhanced visibility into analysis progress, making long-running operations easier to track and debug, by @SUSTAPLE117.
(#419)
🧪 Snapshot Testing Added: Introduced snapshot testing to improve regression detection and testing confidence, by @SUSTAPLE117.
(#401)
⚙️ Go 1.26 Upgrade + Dependency Refresh: Upgraded to Go 1.26 and refreshed dependencies for improved performance and compatibility, by @SUSTAPLE117.
(#412)
🔐 Improved Rule Handling for GitHub Actions: Configured skip actions to be ignored for the github_action_from_unverified_creator_used rule, improving rule accuracy, by @mbarbero.
(#398)
📦 Goreleaser Configuration Updates: Updated release configuration and tooling for improved build and distribution workflows, by @SUSTAPLE117.
(#417), (#418)
🐳 Docker Image Parsing Fixes: Fixed issues with Docker image parsing and purl generation, by @SUSTAPLE117.
(#413)
📄 YAML Parsing Fixes: Resolved YAML parsing errors affecting analysis reliability, by @SUSTAPLE117.
(#414)
🔑 GitHub Fine-Grained PAT Compatibility: Fixed organization repository listing failures when using fine-grained tokens without Issues:Read, by @fproulx-boostsecurity.
(#415)
🧾 SARIF Taxonomy GUID Fix: Corrected SARIF taxonomy GUID issues to ensure proper report compatibility, by @SUSTAPLE117.
(#416)
github/codeql-action from 3.30.5 to 4.31.2. (#370)ossf/scorecard-action from 2.4.2 to 2.4.3. (#371)step-security/harden-runner from 2.13.0 to 2.13.1. (#375)actions/upload-artifact from 4.6.2 to 5.0.0. (#376)actions/setup-go from 5.5.0 to 6.4.0. (#403)goreleaser/goreleaser-action from 6.4.0 to 7.0.0. (#411)actions/deploy-pages from 4.0.5 to 5.0.0. (#410)actions/checkout from 5.0.0 to 6.0.2. (#408)sigstore/cosign-installer across versions 3.9.2 → 4.0.0 → 4.1.1. (#377), (#405)gitlab.com/gitlab-org/api/client-go from 0.151.0 to 0.157.1. (#369)github.com/open-policy-agent/opa from 1.9.0 to 1.10.0. (#372)github.com/mark3labs/mcp-go from 0.41.1 to 0.42.0. (#373)golang.org/x/oauth2 from 0.31.0 to 0.32.0. (#374)golang.org/x/crypto from 0.42.0 to 0.45.0. (#380)For a detailed view of all changes, see the full changelog.
build(deps): bump gitlab.com/gitlab-org/api/client-go from 0.151.0 to 0.157.1 by @dependabot [bot] in #369
Full Changelog: v1.0.8...v1.1.2
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Use case-insensitive matching for Git error "Not a valid object name" by @mdferdousalam in #389
Full Changelog: v1.0.7...v1.0.8
Add more structured metadata fields for programmatic access of LOTP targets by @fproulx-boostsecurity in #386
Full Changelog: v1.0.6...v1.0.7
Nothing published for this version
Add structured metadata fields to findings for programmatic access by @fproulx-boostsecurity in #385
Full Changelog: v1.0.5...v1.0.6
Add GHSA-pwf7-47c3-mfhx to OSV advisories database by @kawsarahmedbhuiyan in #381
Full Changelog: v1.0.4...v1.0.5
Add Boost Sarif Metadata by @SUSTAPLE117 in #367
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →